ATT&CKGroupsEXOTIC LILY

EXOTIC LILY

G1011

Threat group.View on attack.mitre.org

About this group

EXOTIC LILY is a financially motivated group that has been closely linked with Wizard Spider and the deployment of ransomware including Conti and Diavol. EXOTIC LILY may be acting as an initial access broker for other malicious actors, and has targeted a wide range of industries including IT, cybersecurity, and healthcare since at least September 2021.

Techniques used15

Procedure examples15

TechniqueProcedure example
T1102
Web Service

EXOTIC LILY has used file-sharing services including WeTransfer, TransferNow, and OneDrive to deliver payloads.

T1203
Exploitation for Client Execution

EXOTIC LILY has used malicious documents containing exploits for CVE-2021-40444 affecting Microsoft MSHTML.

T1204.001
Malicious Link

EXOTIC LILY has used malicious links to lure users into executing malicious payloads.

T1204.002
Malicious File

EXOTIC LILY has gained execution through victims clicking on malicious LNK files contained within ISO files, which can execute hidden DLLs within the ISO.

T1566.001
Spearphishing Attachment

EXOTIC LILY conducted an e-mail thread-hijacking campaign with malicious ISO attachments.

T1566.002
Spearphishing Link

EXOTIC LILY has relied on victims to open malicious links in e-mails for execution.

T1566.003
Spearphishing via Service

EXOTIC LILY has used the e-mail notification features of legitimate file sharing services for spearphishing.

T1583.001
Domains

EXOTIC LILY has registered domains to spoof targeted organizations by changing the top-level domain (TLD) to “.us”, “.co” or “.biz”.

T1585.001
Social Media Accounts

EXOTIC LILY has established social media profiles to mimic employees of targeted companies.

T1585.002
Email Accounts

EXOTIC LILY has created e-mail accounts to spoof targeted organizations.

T1589.002
Email Addresses

EXOTIC LILY has gathered targeted individuals' e-mail addresses through open source research and website contact forms.

T1593.001
Social Media

EXOTIC LILY has copied data from social media sites to impersonate targeted individuals.

T1594
Search Victim-Owned Websites

EXOTIC LILY has used contact forms on victim websites to generate phishing e-mails.

T1597
Search Closed Sources

EXOTIC LILY has searched for information on targeted individuals on business databases including RocketReach and CrunchBase.

T1608.001
Upload Malware

EXOTIC LILY has uploaded malicious payloads to file-sharing services including TransferNow, TransferXL, WeTransfer, and OneDrive.

Software2

Campaigns0

None recorded.

References1

  1. Google EXOTIC LILY March 2022 Open source
    Stolyarov, V. (2022, March 17). Exposing initial access broker with ties to Conti. Retrieved August 18, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.